CVE-2026-54008: Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture...
Added to the CISA Known Exploited Vulnerabilities catalog on 23 Jun 2026. Vendor: AI/ML. Product: artificial intelligence. CVSS score: 8.5.
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backend/open_webui/utils/oauth.py::_process_picture_url calls validate_url(picture_url) on the initial URL only, then invokes aiohttp.ClientSession.get(picture_url, ...) without allo...
Required action: Review and patch if applicable to your AI infrastructure.